Patent · US Active

Forensic analysis

US11032301B2 · kind B2 · utility

69Cited by
2References
26Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 25, 2018
Grant dateJun 8, 2021
Priority date
Expiry dateMar 12, 2039

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A forensic analysis method performed in respect of an endpoint device connected to a computer network. The forensic analysis method comprises collecting file system call data from the endpoint device. The file system call data corresponds to a plurality of system calls relating to file system operations arising from activity performed on the endpoint device. The forensic analysis method also comprises collecting network communication metadata from the endpoint device. The network communication metadata is based on a plurality of system calls relating to communication operations over the computer network arising from activity performed on the endpoint device. The forensic analysis method further comprises detecting first candidate data comprised in one of the collected file system call data and the collected network communication metadata and identifying second candidate data in the other of the collected file system call data and the collected network communication metadata with the second candidate data corresponding to the first candidate data. The forensic analysis method yet further comprises analysing the second candidate data to determine whether or not the first and second c…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.